CVE-2024-4817
Campcodes Online Laundry Management System HTTP Request Parameter manage_user.php resource injection
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
A vulnerability has been found in Campcodes Online Laundry Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file manage_user.php of the component HTTP Request Parameter Handler. The manipulation of the argument id leads to improper control of resource identifiers. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-263938 is the identifier assigned to this vulnerability.
Una vulnerabilidad ha sido encontrada en Campcodes Online Laundry Management System 1.0 y clasificada como crítica. Esta vulnerabilidad afecta a un código desconocido del archivo enable_user.php del componente HTTP Request Parameter Handler. La manipulación del argumento id conduce a un control inadecuado de los identificadores de recursos. El ataque se puede iniciar de forma remota. El exploit ha sido divulgado al público y puede utilizarse. VDB-263938 es el identificador asignado a esta vulnerabilidad.
In Campcodes Online Laundry Management System 1.0 wurde eine kritische Schwachstelle gefunden. Dabei geht es um eine nicht genauer bekannte Funktion der Datei manage_user.php der Komponente HTTP Request Parameter Handler. Durch Manipulation des Arguments id mit unbekannten Daten kann eine improper control of resource identifiers-Schwachstelle ausgenutzt werden. Die Umsetzung des Angriffs kann dabei über das Netzwerk erfolgen. Der Exploit steht zur öffentlichen Verfügung.
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2024-05-13 CVE Reserved
- 2024-05-13 CVE Published
- 2024-05-14 EPSS Updated
- 2024-08-01 CVE Updated
- 2024-08-01 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-99: Improper Control of Resource Identifiers ('Resource Injection')
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
https://vuldb.com/?id.263938 | Technical Description | |
https://vuldb.com/?submit.333055 | Third Party Advisory |
URL | Date | SRC |
---|---|---|
https://github.com/yylmm/CVE/blob/main/Online%20Laundry%20Management%20System/IDOR_manage_user.md | 2024-08-01 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Campcodes Search vendor "Campcodes" | Online Laundry Management System Search vendor "Campcodes" for product "Online Laundry Management System" | 1.0 Search vendor "Campcodes" for product "Online Laundry Management System" and version "1.0" | en |
Affected
|